CVE-2026-13377: WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS SIP Proxy module allows Stored XSS. This vulnerability is an additional unmitigated attack path for CVE-2025-6947.
This issue affects Fireware OS 12.0 up to and including 12.12, 12.5 up to and including 12.5.18, and 2025.1 up to and including 2026.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13377?
The severity of CVE-2026-13377 is rated medium with a CVSS score of 4.8.
How do I fix CVE-2026-13377?
To fix CVE-2026-13377, ensure you update to the latest version of WatchGuard Fireware OS that includes the security patches for this vulnerability.
What type of vulnerability is CVE-2026-13377?
CVE-2026-13377 is a Stored Cross-Site Scripting (XSS) vulnerability in the WatchGuard Fireware OS SIP Proxy module.
What impact does CVE-2026-13377 have on my system?
CVE-2026-13377 can allow an attacker to inject malicious scripts into web pages viewed by users, potentially compromising user data or session information.
Is CVE-2026-13377 related to any other vulnerabilities?
Yes, CVE-2026-13377 is an additional unmitigated attack path for CVE-2025-6947, highlighting the need for comprehensive security measures.